<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to block people who are trying to exploid vulnabillities for a period of time in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-people-who-are-trying-to-exploid-vulnabillities-for/m-p/23660#M17243</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I guess the short answer is: contact your Sales Engineer to file this as a feature request.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PA have today two methods to deal with annoying clients (over time): zone protection and dos protection (unfortunately none of them can today be used as you requested as I know).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check out &lt;A __default_attr="3094" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt; for more information.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 26 Jun 2012 06:59:40 GMT</pubDate>
    <dc:creator>mikand</dc:creator>
    <dc:date>2012-06-26T06:59:40Z</dc:date>
    <item>
      <title>How to block people who are trying to exploid vulnabillities for a period of time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-people-who-are-trying-to-exploid-vulnabillities-for/m-p/23659#M17242</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our PA's are using the thread prevention system which drops traffic that is trying to exploid vulnabillities, do DoS attacks etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All works very nice - but it's only affecting the attempt on an individual basis.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;F. ex. - someone performs a "DNS ANY Queries Brute Force DOS Attack" and gets blocked. But then the same source re-tries shortly after. And again and again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm looking for a way to automatically block the source IP for a period of time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Say that source IP 119.147.138.171 gets caught trying to do a "DNS ANY Queries Brute Force DOS Attack". If the source IP does this a number of times - then this IP should be completly blocked for a prolonged period of time - f. ex 24h&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now the big question is - how do we do that ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Br&lt;/P&gt;&lt;P&gt;Jørgen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Jun 2012 21:14:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-people-who-are-trying-to-exploid-vulnabillities-for/m-p/23659#M17242</guid>
      <dc:creator>sitecore</dc:creator>
      <dc:date>2012-06-25T21:14:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to block people who are trying to exploid vulnabillities for a period of time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-people-who-are-trying-to-exploid-vulnabillities-for/m-p/23660#M17243</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I guess the short answer is: contact your Sales Engineer to file this as a feature request.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PA have today two methods to deal with annoying clients (over time): zone protection and dos protection (unfortunately none of them can today be used as you requested as I know).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check out &lt;A __default_attr="3094" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt; for more information.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jun 2012 06:59:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-people-who-are-trying-to-exploid-vulnabillities-for/m-p/23660#M17243</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-06-26T06:59:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to block people who are trying to exploid vulnabillities for a period of time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-people-who-are-trying-to-exploid-vulnabillities-for/m-p/23661#M17244</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can indeed do this. In PAN-OS 4.0, a new action called block-ip was introduced. You can block based on source IP or source and destination IP pair. You can use this action in the vulnerability protection profile &amp;gt; Exceptions, find the signature and change the action to block-ip. Set the time from 1-3600 seconds. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the zone protection profile, you can also use the block-ip action associated with the reconnaissance protection for port scans and host sweeps. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jun 2012 15:23:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-people-who-are-trying-to-exploid-vulnabillities-for/m-p/23661#M17244</guid>
      <dc:creator>fredallee</dc:creator>
      <dc:date>2012-06-26T15:23:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to block people who are trying to exploid vulnabillities for a period of time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-people-who-are-trying-to-exploid-vulnabillities-for/m-p/23662#M17245</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;*doh* forgot about that one &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When block-ip is activated, will each attempt from the blocked client still be logged (or if the PA box will no longer log the client attempts - can one override it so it will)?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jun 2012 18:44:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-people-who-are-trying-to-exploid-vulnabillities-for/m-p/23662#M17245</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-06-26T18:44:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to block people who are trying to exploid vulnabillities for a period of time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-people-who-are-trying-to-exploid-vulnabillities-for/m-p/23663#M17246</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Spot on - thanks a lot &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Br&lt;/P&gt;&lt;P&gt;Jørgen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2012 16:08:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-people-who-are-trying-to-exploid-vulnabillities-for/m-p/23663#M17246</guid>
      <dc:creator>sitecore</dc:creator>
      <dc:date>2012-06-27T16:08:15Z</dc:date>
    </item>
  </channel>
</rss>

